Public scope snapshot

Pick the scope.
Know the boundary.

HackerOne, Bugcrowd, Intigriti, YesWeHack, and Federacy snapshots normalized from bounty-targets-data ↗, with structured scope, exclusions, and published maximum payouts when available.

Convenience is not authorization. Scope changes. Open the current program brief immediately before testing.

The index narrows the search. The current program brief controls the hunt.
940indexed programs
619marked rewards in source
387published maxima
46,014in-scope assets
4,445explicit exclusions
2026-08-22snapshot fetched
Program finder

Cut the directory down to a huntable surface.

Search is punctuation-tolerant and matches every term in any order. Bugcrowd maxima use its dollar display. Intigriti keeps each program's supplied currency. Payout sorting is enabled only after selecting one currency.

Candidate scope check

Where is an asset listed?

Find candidate programs and conflicting exclusions. Results still require a manual policy check.

Loading program index…Normalized from bounty-targets-data public platform snapshots.
Query scopes through MCP →

Loading the public scope ledger…